This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-canvas-13.0-wheezy-amd64-vmdk.zip.sig gpg: Signature made Wed Oct 16 08:20:48 UTC 2013 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key" For your convenience we also include file checksums: * sha1sum 9bdbc939f573d0b26f10cdcd18366258e8695b82 * md5sum 9cc5f82a5839d74960a1f1df53276021 You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAABAgAGBQJSXkxHAAoJEIXCXpWhbrlNx6AH/ixse+YIt1TqtNA+ddPEjVNI jQiGFXFnvMPmsVbYEt7m6TKWtZcM8AHlSsbY7It6eqm/LMricuYE+GT0nWpyl5ME IMsQlTt5e7bQKsVRaaYeEP16s28OrzpXW9zn/yBadrxWgvAV8qSF8npsFaoiLpT1 Z6HXkkziZ/kt+LJ3J9OpEhMpJgDalfnoHjFoIXT2/EwzpDiImeoKMbI5zxfnqCnz S9jkbyZMYRm7EUaBDcovn+THqUjOeZ/oqGy7NxbIWKUkiW2w4tGd8xqLoa+YtY3Y n2eQtAq2AhtUYRMSziSIG4m2tbxiHXYJPlGChffVNCoj7HLZMhI++1GHnf+5nGM= =I/iU -----END PGP SIGNATURE-----